CVE-2025-36226: Multiple vulnerabilities in IBM Aspera Faspex
IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Aspera Faspex 5 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36226?
CVE-2025-36226 is classified as a moderate severity vulnerability due to its potential to allow authenticated users to execute arbitrary JavaScript code.
How do I fix CVE-2025-36226?
To fix CVE-2025-36226, update IBM Aspera Faspex to version 5.0.14.4 or later, which addresses the cross-site scripting vulnerability.
Who is affected by CVE-2025-36226?
IBM Aspera Faspex versions 5.0.0 through 5.0.14.3 are affected by CVE-2025-36226.
What types of attacks can CVE-2025-36226 enable?
CVE-2025-36226 enables cross-site scripting (XSS) attacks, allowing attackers to embed malicious scripts in the web UI.
Is authentication required to exploit CVE-2025-36226?
Yes, authentication is required to exploit CVE-2025-36226, as it allows embedded JavaScript only for authenticated users.